← Vulnerability feed

Vulnerability record · CVE-2018-6513 · published 11 June 2018

CVE-2018-6513: Puppet untrusted search path vulnerability

Puppet · Puppet

Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2, were vulnerable to an attack where an unprivileged user on Windows agents could write custom facts that can escalate privileges on the next puppet run. This was possible through the loading of shared libraries from untrusted paths.

8.8 CVSS 3.0 High EPSS 1.1% · top 35.3% CWE-426 · Untrusted search path
8.8CVSS 3.0 base score, v2 6.5
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2, were vulnerable to an attack where an unprivileged user on Windows agents could write custom facts that can escalate privileges on the next puppet run. This was possible through the loading of shared libraries from untrusted paths.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-6513 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-5309Puppet enterprise vulnerabilityVersions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.EPSS 0.50%9.8CVE-2023-2530Puppet enterprise vulnerabilityA privilege escalation allowing remote code execution was discovered in the orchestration service.EPSS 1.1%9.8CVE-2021-27023Puppet agent vulnerabilityA flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different ho…EPSS 1.4%9.8CVE-2019-10694Puppet enterprise hard-coded credentials vulnerabilityThe express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin passwor…EPSS 1.1%9.8CVE-2018-11749Puppet enterprise cleartext transmission vulnerabilityWhen users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affec…EPSS 0.76%9.8CVE-2018-6512Puppet pe-razor-server code injection vulnerabilityThe previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet …EPSS 1.9%9.8CVE-2016-2788Puppet marionette collective improper access control vulnerabilityMCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the …EPSS 2.3%9.8CVE-2016-2786Puppet agent improper input validation vulnerabilityThe pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certifica…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2018-6513), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.